Openbsd OpenSSH vulnerabilities
136 known vulnerabilities affecting openbsd/openssh.
Total CVEs
136
CISA KEV
0
Public exploits
24
Exploited in wild
10
Severity breakdown
CRITICAL13HIGH48MEDIUM60LOW15
Vulnerabilities
Page 5 of 7
CVE-2017-15906P4MEDIUMCVSS 5.3fixed in 7.62017-10-26
CVE-2017-15906 [MEDIUM] CWE-732 CVE-2017-15906: The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write ope
The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.
nvdosv
CVE-2013-4548P4MEDIUMCVSS 6.0v6.2v6.32013-11-08
CVE-2013-4548 [MEDIUM] CWE-264 CVE-2013-4548: The mm_newkeys_from_blob function in monitor_wrap.c in sshd in OpenSSH 6.2 and 6.3, when an AES-GCM
The mm_newkeys_from_blob function in monitor_wrap.c in sshd in OpenSSH 6.2 and 6.3, when an AES-GCM cipher is used, does not properly initialize memory for a MAC context data structure, which allows remote authenticated users to bypass intended ForceCommand and login-shell restrictions via packet data that provides a crafted callback address.
nvdosv
CVE-2018-15919P4MEDIUMCVSS 5.3≥ 5.9, ≤ 7.82018-08-28
CVE-2018-15919 [MEDIUM] CWE-200 CVE-2018-15919: Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attacker
Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not want to treat such a username enumeration (or "oracle") as a vulnerability.'
nvd
CVE-2015-5352P4MEDIUMCVSS 4.3≤ 6.82015-08-03
CVE-2015-5352 [MEDIUM] CWE-264 CVE-2015-5352: The x11_open_helper function in channels.c in ssh in OpenSSH before 6.9, when ForwardX11Trusted mode
The x11_open_helper function in channels.c in ssh in OpenSSH before 6.9, when ForwardX11Trusted mode is not used, lacks a check of the refusal deadline for X connections, which makes it easier for remote attackers to bypass intended access restrictions via a connection outside of the permitted time window.
nvdosv
CVE-2004-2760P4MEDIUMCVSS 6.8v3.5v3.5p12004-12-31
CVE-2004-2760 [MEDIUM] CVE-2004-2760: sshd in OpenSSH 3.5p1, when PermitRootLogin is disabled, immediately closes the TCP connection after
sshd in OpenSSH 3.5p1, when PermitRootLogin is disabled, immediately closes the TCP connection after a root login attempt with the correct password, but leaves the connection open after an attempt with an incorrect password, which makes it easier for remote attackers to guess the password by observing the connection state, a different vulnerability than CVE-2
nvdosv
CVE-2003-0695P4HIGHCVSS 7.5≤ 3.7.12003-10-06
CVE-2003-0695 [HIGH] CVE-2003-0695: Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of
Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate function in channels.c, a different vulnerability than CVE-2003-0693.
nvdosv
CVE-2003-0682P4HIGHCVSS 7.5≤ 3.7.12003-10-06
CVE-2003-0682 [HIGH] CVE-2003-0682: "Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities
"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695.
nvdosv
CVE-2001-1507P4HIGHCVSS 7.5v3.0v3.0p12001-12-31
CVE-2001-1507 [HIGH] CVE-2001-1507: OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate users, which could allow
OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate users, which could allow remote attackers to login unchallenged.
nvdosv
CVE-2026-59995P4MEDIUMCVSS 5.4fixed in 10.42026-07-08
CVE-2026-59995 [MEDIUM] CWE-23 CVE-2026-59995: sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
nvd
CVE-2001-1459P4HIGHCVSS 7.5v2.1v2.1.1+6 more2001-06-19
CVE-2001-1459 [HIGH] CVE-2001-1459: OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if command
OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, which allows local users to bypass resource limits (rlimits) set in pam.d.
nvdosv
CVE-2000-1169P4HIGHCVSS 7.5v2.22001-01-09
CVE-2000-1169 [HIGH] CVE-2000-1169: OpenSSH SSH client before 2.3.0 does not properly disable X11 or agent forwarding, which could allow
OpenSSH SSH client before 2.3.0 does not properly disable X11 or agent forwarding, which could allow a malicious SSH server to gain access to the X11 display and sniff X11 events, or gain access to the ssh-agent.
nvd
CVE-2001-0816P4HIGHCVSS 7.5≤ 2.9.92001-12-06
CVE-2001-0816 [HIGH] CVE-2001-0816: OpenSSH before 2.9.9, when running sftp using sftp-server and using restricted keypairs, allows remo
OpenSSH before 2.9.9, when running sftp using sftp-server and using restricted keypairs, allows remote authenticated users to bypass authorized_keys2 command= restrictions using sftp commands.
nvd
CVE-2026-59996P4MEDIUMCVSS 5.4fixed in 10.42026-07-08
CVE-2026-59996 [MEDIUM] CWE-23 CVE-2026-59996: scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when th
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
nvd
CVE-2001-1585P4MEDIUMCVSS 6.8v2.3.12001-12-31
CVE-2001-1585 [MEDIUM] CWE-287 CVE-2001-1585: SSH protocol 2 (aka SSH-2) public key authentication in the development snapshot of OpenSSH 2.3.1, a
SSH protocol 2 (aka SSH-2) public key authentication in the development snapshot of OpenSSH 2.3.1, available from 2001-01-18 through 2001-02-08, does not perform a challenge-response step to ensure that the client has the proper private key, which allows remote attackers to bypass authentication as other users by supplying a public key from that user'
nvd
CVE-2008-1657P4MEDIUMCVSS 6.5v4.4v4.4p1+4 more2008-04-02
CVE-2008-1657 [MEDIUM] CWE-264 CVE-2008-1657: OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config Fo
OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc session file.
nvdosv
CVE-2015-6563P4MEDIUMCVSS 6.4≤ 6.92015-08-24
CVE-2015-6563 [MEDIUM] CWE-20 CVE-2015-6563: The monitor component in sshd in OpenSSH before 7.0 on non-OpenBSD platforms accepts extraneous user
The monitor component in sshd in OpenSSH before 7.0 on non-OpenBSD platforms accepts extraneous username data in MONITOR_REQ_PAM_INIT_CTX requests, which allows local users to conduct impersonation attacks by leveraging any SSH login access in conjunction with control of the sshd uid to send a crafted MONITOR_REQ_PWNAM request, related to monitor.c and
nvdosv
CVE-2006-5052P4MEDIUMCVSS 5.0v1.2v1.2.1+54 more2006-09-27
CVE-2006-5052 [MEDIUM] CVE-2006-5052: Unspecified vulnerability in portable OpenSSH before 4.4, when running on some platforms, allows rem
Unspecified vulnerability in portable OpenSSH before 4.4, when running on some platforms, allows remote attackers to determine the validity of usernames via unknown vectors involving a GSSAPI "authentication abort."
nvdosv
CVE-2003-0787P4HIGHCVSS 7.5v3.7.1v3.7.1p12003-11-17
CVE-2003-0787 [HIGH] CVE-2003-0787: The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an a
The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an array of pointers, which allows attackers to modify the stack and possibly gain privileges.
nvdosv
CVE-2006-4925P4MEDIUMCVSS 5.0v4.52006-09-29
CVE-2006-4925 [MEDIUM] CVE-2006-4925: packet.c in ssh in OpenSSH allows remote attackers to cause a denial of service (crash) by sending a
packet.c in ssh in OpenSSH allows remote attackers to cause a denial of service (crash) by sending an invalid protocol sequence with USERAUTH_SUCCESS before NEWKEYS, which causes newkeys[mode] to be NULL.
nvdosv
CVE-2026-59997P4MEDIUMCVSS 5.4fixed in 10.42026-07-08
CVE-2026-59997 [MEDIUM] CWE-1284 CVE-2026-59997: internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, whi
internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.
nvd